Our privacy commitment

At Infinite Retail Pty Ltd Australian Business Number 19 158 215 984, we are committed to high standards of conduct in all our business activities, which includes protecting your privacy in accordance with the applicable privacy law. This policy describes how we will manage your personal information in an open, transparent, and lawful way.

This Privacy Policy applies to the personal information we, or any subsidiaries of Super Retail Group Limited, collect, store, maintain and use about you as our customers, visitors to our websites and stores, users and contributors to social media and other digital services, job applicants, and members of the public. By using our website, engaging with us (including via social media or other channels), or otherwise acquiring any product or service from us, you agree to and accept the contents of this Privacy Policy.

Why do we collect and use your personal information?

When we refer to personal information, we mean information which identifies you as an individual or from which your identity can be reasonably determined.

We collect and deal with your personal information so that we can better:

assist you with your transactions with us;

tell you about and improve our products, services, and experiences that we offer to you;

support our business administration and related functions;

accept/consider job applications, and send you opportunities that may be of interest to you;

allow you to join and participate in our club memberships;

assist with any enquiries you make;

meet our legal obligations; and

for other reasons you might reasonably expect us to use your personal information for.

Without your personal information, we may not be able to provide our products or services to you.

What type of personal information do we collect?

When we collect and hold personal information, it may include details such as your name, address, email, telephone number, date of birth, gender, stated or likely preferences and interests (e.g. whether you may be interested in particular products or promotions), and any other details reasonably related to your shopping experience (e.g. you might provide sizing details when shopping for apparel) or dealings with us (e.g. job applications).

How do we collect your personal information?

General collection

We may collect personal information about you during your interactions with us including when:

you shop with us on our websites;

you make an enquiry with us;

you join our club membership programs;

you participate in a survey, promotion or competition; and

you visit or contribute to our online channels such as our websites, social media platforms and other digital services.

Cookies and other technologies

We may collect personal information about you using cookies and other technologies when you visit our websites to create a better and more consistent shopping experience that is more personal to you.

We use cookies which are small files stored on your device that allows our website to recognise a particular device or browser. We use cookies and other technologies to improve site functionalities (e.g. to help you navigate our website or remember your preferences), measure the effectiveness of our marketing campaigns, and tailor advertisements to make them more relevant to you.

You can delete cookies that are already on your computer by going to the “settings” section in your browser which should provide instructions on how to locate the file or directory that stores cookies. Please note that by deleting or disabling future cookies, your user experience may be affected and you might not be able to use certain functions of our website.

Social media and other third party websites

We use a number of third party websites and social media platforms including Twitter, Instagram, LinkedIn, Facebook and YouTube.

We may make use of any information that you make public when you use any such services or platforms. Such information available for use by us may include images and text relating to us or our products, services, promotions, events, club memberships and club cards.

You may be able to access other third party websites through our websites. If the operators of those third party websites collect information about you, we may have arrangements in place with those third parties that allows us to collect or have access to that information.

How do we use your personal information?

General use

We may use your personal information to provide our club memberships, communicate with you or respond to an enquiry/complaint/application, and fulfill your orders.

Direct marketing

We will use or disclose your personal information for direct marketing purposes if you have provided your information for that purpose or if you have subsequently provided consent for your information to be used in this way.

We may contact you from time to time (by mail, telephone, email, SMS, social media platforms or any other appropriate means) with information about our (or our ‘related companies’) products and services and our business partners, which we think may be of interest to you. We may also provide relevant marketing to you whether directly or through online advertisement networks or other third parties services such as those operated by Google, based on your browsing activities, information collected by surveys, website analytics, online behavioural advertising, and other means.

You may choose not to receive direct marketing communications from us by ‘opting-out’. Each of our direct marketing materials will tell you how to do this and we will comply with your request within a reasonable timeframe.

Sharing your personal information

We may need to disclose your personal information to third parties who perform functions or services in connection with our business, such as delivery; product repair or recall; payment processing; marketing; banking; mailing functions; gateway provision; insurance; document management; information technology services including data storage, hosting and security; employment matters; for operation of our websites; or where we are otherwise required to by law. We may also disclose personal information to our related companies, and to other third parties where you have specifically consented to the disclosure of information to those third parties.

Overseas disclosure of your personal information

Some of our third party service providers have operations overseas or are located overseas. In order for them to provide their services to us (e.g. storage and processing of our data, collection of personal information in a different country to your location), we may have to send your personal information overseas. Before we do so, we will take reasonable steps to ensure that our third party service providers do not breach the relevant privacy laws in relation to your personal information.

We will ensure that any overseas sharing of personal information is done in a way which requires compliance with privacy and security industry standards, both during transit and at the overseas destination.

Due to the number of third party services providers which we engage with from time to time, it is not practicable to provide an exhaustive list of every country where your personal information may be sent. However, it is likely that your personal information will be sent to the following countries: China, Germany, India, New Zealand, Singapore, Switzerland, United Kingdom and United States.

We may also disclose your personal information within our related companies located in Australia, China, New Zealand, and from time to time, in other countries.

How do we secure your personal information?

Our websites

Even though our websites are professionally hosted and operate in a secure environment, there is always a risk in transmitting your personal information via the Internet. To make sure you are accessing a secure server, please check for the unbroken key or closed lock symbol generally located either at the bottom left or top right of your browser window. You can also check this by looking at the URL. If the URL is secure, then the first characters will read ‘https’ rather than just ‘http’.

We are compliant with the Payment Card Industry Data Security Standard (PCI DSS) which is an information security standard for organisations that handle credit card data. This means that your credit card details will be handled using secure processes when you shop with us online and in-store. However, please do not enter any credit card details when contacting us via email or through our website “Contact Us” form. Credit card details will not be encrypted in these situations and will not be secure

Security of your personal information

We will take reasonable steps to protect your personal information, including from misuse, interference and unauthorised access or disclosure. We require our team members to adhere to our internal information security policies to safeguard your personal information at all times.

If we no longer need your personal information, then we may destroy or de-identify the information.

If we become aware that your information has been subjected to unauthorised access, we will report such breach as required by law.

We hold personal information in a number of ways, including:

as part of customer records and other electronic documents which are stored in our information technology systems and servers or those operated by third parties who provide services to us in connection with our business; and

by securely storing hard copy documents at our various premises and using third party document management and archiving services.

Remaining anonymous

When practicable, you may choose not to identify yourself when dealing with us. You also may elect to use a pseudonym to protect your identity.

How do you access and correct your personal information?

If you wish to access or correct any of your personal information we hold, please contact our Privacy Officer whose details are located below. We will provide you with access to your personal information in a reasonable period of time, except in limited circumstances (such as if the access would pose a serious threat to the life, health or safety of another person or where such access would unreasonably impact on the privacy of others).

Before we provide you with access to your personal information we will require proof of identity. Please provide as much detail as you can about the information you are requesting, in order to help us retrieve it. If we refuse your request or are unable to provide you with access to your personal information or are unable to provide it in the manner requested by you, we will provide a written response outlining our reasons.

Sometimes your personal information that we hold will become out of date. Please immediately advise us of any change to your personal information and we will amend our records accordingly.

Obtaining a copy of this policy

The current version of this Privacy Policy is available on our website. If you need a copy of this Privacy Policy in a different form, please ask us and we will try to meet your request. If we make any changes to this Privacy Policy, we will place the updated policy on our website.

What if you are not happy with how we treat your personal information?

If you have any questions or would like to raise any concerns about your personal information, please email, or write to us. As always, we value your feedback and ideas.

If you make a complaint with us regarding your personal information, we will aim to respond to your compliant within 30 days. If you are not happy with our response, please let us know and we will aim to address any further concerns you have. If you are still not happy with our response, you may wish to contact the Office of the Australian Information Commission (OAIC), whose details are listed below.

Further information on privacy

You can obtain further general information about your privacy rights and Commonwealth privacy law by contacting the OAIC: